OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Zimbra Collaboration Suite (ZCS) Session Replay Vulnerability

brianwarehimegmail.com
Date: Fri Sep 13 2013 - 13:16:20 CDT


Product: Zimbra Collaboration Suite
Vendor: VMWare
Vulnerable Version: 6.0.16 and probably prior
Tested Version: 6.0.16
Vendor Notification: 09/03/2013
Public Disclosure: 09/13/2013
Vulnerability Type: Authentication Bypass by Capture-replay (CWE-294)
CVE: CVE-2013-5119
Discovered and Provided By: Brian Warehime (Aplura LLC)

----------------------------------------------------------------------

Advisory Details:

A vulnerability exists in Zimbra Collaboration Suite (ZCS) which can be exploited to bypass authentication by replaying a captured session token. A remote attacker can sniff network traffic and obtain an authorized user's session token and modify the token on the attacker's machine to replay the token and successfully log in. If an attacker can capture the ZM_AUTH_TOKEN after a user has successfully logged in, the attacker can then create a new ZM_AUTH_TOKEN with the same information and log in, even after the other user logs out.

--------------------------------------------------------------------------------------------------

Solution:

Upgrade to the latest version of ZCS.